CVE-2026-13622: Red Hat Container Native Virtualization 4.12

High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside the target virt-launcher pod via /proc/<pid>/root/ paths using net.Dial() without symlink protection. These socket paths reside in qemu-owned directories writable by the virt-launcher user. An attacker with namespace edit and pods/exec permissions can replace a migration proxy socket with a symlink to the host CRI-O socket. Because virt-handler runs as root in the host mount namespace, absolute symlink targets resolve against the host filesystem, and the bidirectional io.Copy proxy relays attacker-controlled bytes to the container runtime, enabling full node compromise.

Affected products

  • Red Hat Red Hat Container Native Virtualization 4.12: before 1785837722 (fixed in 1785837722)
  • Red Hat Red Hat Container Native Virtualization 4.13: before 1786346596 (fixed in 1786346596)
  • Red Hat Red Hat Container Native Virtualization 4.14: before 1786309624 (fixed in 1786309624)
  • Red Hat Red Hat Container Native Virtualization 4.15: before 1786347656 (fixed in 1786347656)
  • Red Hat Red Hat Container Native Virtualization 4.16: before 1786030071 (fixed in 1786030071)
  • Red Hat Red Hat Container Native Virtualization 4.17: before 1786348529 (fixed in 1786348529)
  • Red Hat Red Hat Container Native Virtualization 4.18: before 1786130068 (fixed in 1786130068)
  • Red Hat Red Hat Container Native Virtualization 4.19: before 1786334215 (fixed in 1786334215)
  • Red Hat Red Hat Container Native Virtualization 4.20: before 1785831334 (fixed in 1785831334)
  • Red Hat Red Hat Container Native Virtualization 4.21: before 1785829701 (fixed in 1785829701)
  • Red Hat Red Hat Container Native Virtualization 4.22: before 1785140336 (fixed in 1785140336)

Published 2026-08-12. Last modified 2026-09-21.